Proofpoint identified an active Microsoft 365 password-spraying campaign, tracked as UNK_CondorFiltration, that used artifacts linked to the TeamFiltration offensive framework. From July 21 to August 16, the operator generated 32,825 authentication attempts against 5,714 accounts in 28 tenants—primarily Chilean retail and financial organizations—from 1,487 AWS EC2 IP addresses. Seven accounts at a major Chilean retailer were compromised; each was an unmanaged functional or service account with a default, predictable, or unrotated password and no MFA.
After gaining access, the actor used a German VPN node to probe the victim's corporate VPN and access Azure Portal, OfficeHome, and SharePoint Online, while also requesting Microsoft Graph API tokens. Activity could support reconnaissance or collection from email, Teams, OneDrive, and SharePoint, but available sign-in telemetry does not confirm data exfiltration. Organizations should inventory dormant and non-human Microsoft 365 accounts, rotate credentials, eliminate default passwords, and enforce MFA or equivalent controls for service identities.

Get the actors, campaigns, and ATT&CK mapping behind it.
5 events from the most recent confirmed update back to the earliest known activity.
Within roughly 90 seconds of one compromise, the operator used German VPN IP address 149.88.104.19 to probe the victim's corporate VPN, access Azure Portal, OfficeHome, and SharePoint Online, and request tokens usable with Microsoft Graph or external APIs. MFA or conditional-access controls blocked the corporate-VPN attempt, while Azure Portal prompted for MFA enrollment on the compromised account.
During a third wave against a major Chilean retailer, UNK_CondorFiltration compromised seven unmanaged functional or service accounts that lacked MFA and apparently retained default or predictable passwords. Six accounts were compromised within seven minutes; the retailer accounted for 3,038 targeted accounts and 25,715 authentication events.
A second campaign wave targeted another major Chilean financial institution, peaking at about 1,520 targeted accounts on July 27. The operator made 1,536 authentication attempts against approximately 114 accounts, including 782 attempts against 57 senior accounts.
The first observed wave of the UNK_CondorFiltration Microsoft 365 password-spraying campaign targeted roughly 100 to 120 accounts per day at two major Chilean banking institutions, using AWS EC2 infrastructure.
Proofpoint previously reported that the TeamFiltration-related UNK_SneakyStrike cluster targeted more than 80,000 accounts across hundreds of organizations' cloud tenants using the open-source framework.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.